Implement researched Guix package outcome for #383: [Guix packaging] Grippy Socks #689

Closed
opened 2026-09-05 05:38:24 +00:00 by htayj · 5 comments
htayj commented 2026-09-05 05:38:24 +00:00 (Migrated from github.com)

Context

This delivery ticket was created from research issue #383 ([Guix packaging] Grippy Socks).

The host-validated research finding follows:

Canonical upstream is the author mirror https://github.com/CruiserOne/Daedalus at tag v3.5, fixed commit 32af46ddf22e53c9bfd7bd7eacca1e249c60a5e8 (tag resolves to that commit); official source archive https://www.astrolog.org/labyrnth/daedalus/dae35zip.zip has SHA-256 19ec305be102c8425d8a0d16475ba1ba9b7b04e3bd58c341525b808d81f364b0. The official Daedalus 3.5 documentation identifies GRIPSOX.DS as the Grippy Socks script, dates 3.5 to 2024-10-31, and says the distribution includes complete C++ source and a Unix Makefile; the Makefile builds with g++ and -lm, while util.h documents the command-line Unix mode obtained by disabling WIN. The source headers and retained license.htm identify Walter D. Pullen and GPL-2.0-or-later; all shipped Grippy Socks content is from this one fixed upstream origin. The script has no external file references or separately fetched dependencies: its map/bitmap content is embedded in gripsox.ds, and the package should install only that script, the rebuilt engine, and upstream license/author documentation, with no fonts, tiles, sounds, submodules, language registries, updater, telemetry, runtime download, or network path. There is no same-project package in the local channel or audit files. tay/packages/dragonslayer.scm is a distinct Daedalus-script package with issue #681 runtime contract/evidence; it shares the engine but installs dragon.ds, so grippy-socks is a separately justified variant, not a duplicate. Deliver tay/packages/grippy-socks.scm with gnu-build-system/git-fetch at the fixed commit (the existing Daedalus precedent records the matching Git checkout hash base32 0fdzx2zzqbd3p99yljksmbh0s3mbzzmq2dq42a9yz5rfkn9gjy2r), no configure phase, and native gcc-toolchain plus bash-minimal/coreutils-minimal for the wrapper. Apply the proven Unix patches: disable WIN and PC, use unsigned int for the bitmap dword on LP64, and add the Linux-sized-delete compatibility definition; build with upstream make daedalus. Install the engine privately under libexec and a package-owned grippy-socks launcher that uses a state directory only for ordinary interactive play, never writes the store, and supports exactly --smoke. That mode must load the installed gripsox.ds and perform a deterministic normal movement/interaction through the command-line engine before printing the declared marker. Research could not run Guix because the host explicitly provides no daemon; this is an authoritative metadata assessment, not package proof. Delivery acceptance: preflight package load/parser, guix lint -L . grippy-socks with no package-specific findings, offline guix build -L . --no-grafts --no-substitutes grippy-socks, upstream has no test target so run the bounded wrapper smoke, then guix build -L . --no-grafts --no-substitutes --check grippy-socks. The isolated proof must use fresh HOME/XDG directories, empty PATH and proxy-disabled network, bounded-validation with util-linux unshare --user --map-root-user --net --fork, assert stdout GRIPPY_SOCKS_SMOKE_OK plus a visible Grippy Socks start/gameplay line, verify no files appear in HOME/XDG/work, compare the output NAR hash before/after, and assert the installed tree is non-writable; capture the screenshot at .goocastle/evidence/issue-383.png. Retain license.htm and the upstream author notices in share/doc/grippy-socks.

Acceptance criteria

  • Implement the viable package change identified in the host-validated research finding.
  • Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding.
  • Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure.

Runtime evidence contract

Implementation workflow: guix-package-quality-gates
Reviewed contract file: .goocastle/runtime-evidence-contracts.json
Required proof phase: safe-package-proof; screenshot phase: runtime-screenshot
Evidence adapter: github-issue-comment
Copy this reviewed contract into the named file before running the package proof workflow.

{
  "version": 1,
  "contracts": [
    {
      "issueNumber": 689,
      "packageName": "grippy-socks",
      "packageModulePath": "tay/packages/grippy-socks.scm",
      "artifactPath": ".goocastle/evidence/issue-689.png",
      "runtime": {
        "executable": "grippy-socks",
        "invocation": {
          "file": "grippy-socks",
          "args": [
            "--smoke"
          ]
        },
        "successMarker": "GRIPPY_SOCKS_SMOKE_OK"
      }
    }
  ]
}

Imported from GitHub issue/PR. Originally posted by htayj on 2026-09-05T05:38:24Z.

<!-- goocastle-implementation-ticket:sequential-reviewer:383:1:implementation-ready --> ## Context This delivery ticket was created from research issue #383 ([Guix packaging] Grippy Socks). The host-validated research finding follows: Canonical upstream is the author mirror https://github.com/CruiserOne/Daedalus at tag v3.5, fixed commit 32af46ddf22e53c9bfd7bd7eacca1e249c60a5e8 (tag resolves to that commit); official source archive https://www.astrolog.org/labyrnth/daedalus/dae35zip.zip has SHA-256 19ec305be102c8425d8a0d16475ba1ba9b7b04e3bd58c341525b808d81f364b0. The official Daedalus 3.5 documentation identifies GRIPSOX.DS as the Grippy Socks script, dates 3.5 to 2024-10-31, and says the distribution includes complete C++ source and a Unix Makefile; the Makefile builds with g++ and -lm, while util.h documents the command-line Unix mode obtained by disabling WIN. The source headers and retained license.htm identify Walter D. Pullen and GPL-2.0-or-later; all shipped Grippy Socks content is from this one fixed upstream origin. The script has no external file references or separately fetched dependencies: its map/bitmap content is embedded in gripsox.ds, and the package should install only that script, the rebuilt engine, and upstream license/author documentation, with no fonts, tiles, sounds, submodules, language registries, updater, telemetry, runtime download, or network path. There is no same-project package in the local channel or audit files. tay/packages/dragonslayer.scm is a distinct Daedalus-script package with issue #681 runtime contract/evidence; it shares the engine but installs dragon.ds, so grippy-socks is a separately justified variant, not a duplicate. Deliver tay/packages/grippy-socks.scm with gnu-build-system/git-fetch at the fixed commit (the existing Daedalus precedent records the matching Git checkout hash base32 0fdzx2zzqbd3p99yljksmbh0s3mbzzmq2dq42a9yz5rfkn9gjy2r), no configure phase, and native gcc-toolchain plus bash-minimal/coreutils-minimal for the wrapper. Apply the proven Unix patches: disable WIN and PC, use unsigned int for the bitmap dword on LP64, and add the Linux-sized-delete compatibility definition; build with upstream make daedalus. Install the engine privately under libexec and a package-owned grippy-socks launcher that uses a state directory only for ordinary interactive play, never writes the store, and supports exactly --smoke. That mode must load the installed gripsox.ds and perform a deterministic normal movement/interaction through the command-line engine before printing the declared marker. Research could not run Guix because the host explicitly provides no daemon; this is an authoritative metadata assessment, not package proof. Delivery acceptance: preflight package load/parser, guix lint -L . grippy-socks with no package-specific findings, offline guix build -L . --no-grafts --no-substitutes grippy-socks, upstream has no test target so run the bounded wrapper smoke, then guix build -L . --no-grafts --no-substitutes --check grippy-socks. The isolated proof must use fresh HOME/XDG directories, empty PATH and proxy-disabled network, bounded-validation with util-linux unshare --user --map-root-user --net --fork, assert stdout GRIPPY_SOCKS_SMOKE_OK plus a visible Grippy Socks start/gameplay line, verify no files appear in HOME/XDG/work, compare the output NAR hash before/after, and assert the installed tree is non-writable; capture the screenshot at .goocastle/evidence/issue-383.png. Retain license.htm and the upstream author notices in share/doc/grippy-socks. ## Acceptance criteria - Implement the viable package change identified in the host-validated research finding. - Preserve Guix source provenance, licensing, and deterministic build requirements recorded in the finding. - Add and pass a package-specific safe smoke proof using isolated HOME/XDG state before closure. <!-- goocastle-runtime-evidence-contract --> ## Runtime evidence contract Implementation workflow: `guix-package-quality-gates` Reviewed contract file: `.goocastle/runtime-evidence-contracts.json` Required proof phase: `safe-package-proof`; screenshot phase: `runtime-screenshot` Evidence adapter: `github-issue-comment` Copy this reviewed contract into the named file before running the package proof workflow. ```json { "version": 1, "contracts": [ { "issueNumber": 689, "packageName": "grippy-socks", "packageModulePath": "tay/packages/grippy-socks.scm", "artifactPath": ".goocastle/evidence/issue-689.png", "runtime": { "executable": "grippy-socks", "invocation": { "file": "grippy-socks", "args": [ "--smoke" ] }, "successMarker": "GRIPPY_SOCKS_SMOKE_OK" } } ] } ``` <!-- goocastle-runtime-evidence-contract-end --> --- Imported from [GitHub issue/PR](https://github.com/htayj/guix-channel/issues/689). Originally posted by [htayj](https://github.com/htayj) on 2026-09-05T05:38:24Z.
htayj commented 2026-09-05 06:06:22 +00:00 (Migrated from github.com)

Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate.
The failure receipt and task branch provenance remain preserved; inspect the branch and repair the failing gate before retrying.

Bounded failure evidence:
(no failure evidence retained)


Imported from GitHub comment. Originally posted by htayj on 2026-09-05T06:06:22Z.

<!-- goocastle-repair-blocked:689:runtime-screenshot --> Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate. The failure receipt and task branch provenance remain preserved; inspect the branch and repair the failing gate before retrying. Bounded failure evidence: (no failure evidence retained) --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/689#issuecomment-5549864926). Originally posted by [htayj](https://github.com/htayj) on 2026-09-05T06:06:22Z.
htayj commented 2026-09-05 06:29:06 +00:00 (Migrated from github.com)

Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate.
The failure receipt and task branch provenance remain preserved; inspect the branch and repair the failing gate before retrying.

Bounded failure evidence:
Failed command: sh .goocastle/capture-guix-package-screenshot.sh
Exit status: 1
Final failure lines:
[stderr] Workflow phase "runtime-screenshot" failed Caused by: Invalid runtime evidence: capture stdout must end with the GOOCASTLE_RUNTIME_ASSERTION_V1 line


Imported from GitHub comment. Originally posted by htayj on 2026-09-05T06:29:06Z.

<!-- goocastle-repair-blocked:689:runtime-screenshot --> Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate. The failure receipt and task branch provenance remain preserved; inspect the branch and repair the failing gate before retrying. Bounded failure evidence: Failed command: sh .goocastle/capture-guix-package-screenshot.sh Exit status: 1 Final failure lines: [stderr] Workflow phase "runtime-screenshot" failed Caused by: Invalid runtime evidence: capture stdout must end with the GOOCASTLE_RUNTIME_ASSERTION_V1 line --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/689#issuecomment-5549978355). Originally posted by [htayj](https://github.com/htayj) on 2026-09-05T06:29:06Z.
htayj commented 2026-09-05 07:10:00 +00:00 (Migrated from github.com)

Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate.
The failure receipt and task branch provenance remain preserved; inspect the branch and repair the failing gate before retrying.

Bounded failure evidence:
Failed command: sh .goocastle/capture-guix-package-screenshot.sh
Exit status: 1
Final failure lines:
[stderr] Workflow phase "runtime-screenshot" failed Caused by: Invalid runtime evidence: capture stdout must contain the standalone runtime marker "GRIPPY_SOCKS_SMOKE_OK" emitted by the packaged runtime subject


Imported from GitHub comment. Originally posted by htayj on 2026-09-05T07:10:00Z.

<!-- goocastle-repair-blocked:689:runtime-screenshot --> Goocastle blocked this ticket after the bounded repair budget was exhausted for the required command gate. The failure receipt and task branch provenance remain preserved; inspect the branch and repair the failing gate before retrying. Bounded failure evidence: Failed command: sh .goocastle/capture-guix-package-screenshot.sh Exit status: 1 Final failure lines: [stderr] Workflow phase "runtime-screenshot" failed Caused by: Invalid runtime evidence: capture stdout must contain the standalone runtime marker "GRIPPY_SOCKS_SMOKE_OK" emitted by the packaged runtime subject --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/689#issuecomment-5550189167). Originally posted by [htayj](https://github.com/htayj) on 2026-09-05T07:10:00Z.
htayj commented 2026-09-05 07:57:32 +00:00 (Migrated from github.com)

Goocastle verified runtime evidence.

Runtime screenshot

Runtime receipt
  • Package: grippy-socks
  • Safe package proof phase: safe-package-proof
  • Safe package proof argv: ["node","/opt/goocastle/bin/guix-package-proof.mjs","--package-name","grippy-socks","--module-path","tay/packages/grippy-socks.scm","--runtime-json","{&quot;executable&quot;:&quot;grippy-socks&quot;,&quot;invocation&quot;:{&quot;file&quot;:&quot;grippy-socks&quot;,&quot;args&quot;:[&quot;--smoke&quot;]},&quot;successMarker&quot;:&quot;GRIPPY_SOCKS_SMOKE_OK&quot;}"]
  • Screenshot phase: runtime-screenshot
  • Screenshot argv: ["sh",".goocastle/capture-guix-package-screenshot.sh"]
  • Runtime executable (Guix store/profile): /gnu/store/0xbf4haxvsb3x4qfkx239z6gf81qr4pv-grippy-socks-3.5/bin/grippy-socks
  • Runtime invocation: ["/gnu/store/0xbf4haxvsb3x4qfkx239z6gf81qr4pv-grippy-socks-3.5/bin/grippy-socks","--smoke"]
  • Expected runtime invocation: ["grippy-socks","--smoke"]
  • Expected runtime marker: GRIPPY_SOCKS_SMOKE_OK
  • Per-issue runtime contract: .goocastle/runtime-evidence-contracts.json (issue #689, SHA-256 c4c3269bbca6b0b7dff2a11c4ebd809c616a53de5b585b70fa32e65dfee3eade)
  • Artifact path: .goocastle/evidence/issue-689.png
  • Artifact SHA-256: 4a3d78a5853afe7410c441d9c43f7927b7ed890123aa24454e28670c369d4f46
  • Artifact commit: 4247cc3758862127b6941ce4d2d4900a21344943
  • Artifact size/format: 55557 bytes / png

Imported from GitHub comment. Originally posted by htayj on 2026-09-05T07:57:32Z.

<!-- goocastle-runtime-evidence:sequential-reviewer:689:1:4a3d78a5853afe7410c441d9c43f7927b7ed890123aa24454e28670c369d4f46 --> Goocastle verified runtime evidence. ![Runtime screenshot](https://github.com/htayj/guix-channel/blob/4247cc3758862127b6941ce4d2d4900a21344943/.goocastle/evidence/issue-689.png?raw=1) <details><summary>Runtime receipt</summary> - Package: <code>grippy-socks</code> - Safe package proof phase: <code>safe-package-proof</code> - Safe package proof argv: <code>[&quot;node&quot;,&quot;/opt/goocastle/bin/guix-package-proof.mjs&quot;,&quot;--package-name&quot;,&quot;grippy-socks&quot;,&quot;--module-path&quot;,&quot;tay/packages/grippy-socks.scm&quot;,&quot;--runtime-json&quot;,&quot;{\&quot;executable\&quot;:\&quot;grippy-socks\&quot;,\&quot;invocation\&quot;:{\&quot;file\&quot;:\&quot;grippy-socks\&quot;,\&quot;args\&quot;:[\&quot;--smoke\&quot;]},\&quot;successMarker\&quot;:\&quot;GRIPPY_SOCKS_SMOKE_OK\&quot;}&quot;]</code> - Screenshot phase: <code>runtime-screenshot</code> - Screenshot argv: <code>[&quot;sh&quot;,&quot;.goocastle/capture-guix-package-screenshot.sh&quot;]</code> - Runtime executable (Guix store/profile): <code>/gnu/store/0xbf4haxvsb3x4qfkx239z6gf81qr4pv-grippy-socks-3.5/bin/grippy-socks</code> - Runtime invocation: <code>[&quot;/gnu/store/0xbf4haxvsb3x4qfkx239z6gf81qr4pv-grippy-socks-3.5/bin/grippy-socks&quot;,&quot;--smoke&quot;]</code> - Expected runtime invocation: <code>[&quot;grippy-socks&quot;,&quot;--smoke&quot;]</code> - Expected runtime marker: <code>GRIPPY_SOCKS_SMOKE_OK</code> - Per-issue runtime contract: <code>.goocastle/runtime-evidence-contracts.json (issue #689, SHA-256 c4c3269bbca6b0b7dff2a11c4ebd809c616a53de5b585b70fa32e65dfee3eade)</code> - Artifact path: <code>.goocastle/evidence/issue-689.png</code> - Artifact SHA-256: <code>4a3d78a5853afe7410c441d9c43f7927b7ed890123aa24454e28670c369d4f46</code> - Artifact commit: <code>4247cc3758862127b6941ce4d2d4900a21344943</code> - Artifact size/format: <code>55557 bytes / png</code> </details> --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/689#issuecomment-5550432429). Originally posted by [htayj](https://github.com/htayj) on 2026-09-05T07:57:32Z.
htayj commented 2026-09-05 07:57:36 +00:00 (Migrated from github.com)

Completed by Goocastle


Imported from GitHub comment. Originally posted by htayj on 2026-09-05T07:57:36Z.

Completed by Goocastle --- Imported from [GitHub comment](https://github.com/htayj/guix-channel/issues/689#issuecomment-5550432705). Originally posted by [htayj](https://github.com/htayj) on 2026-09-05T07:57:36Z.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tay/guix-channel#689
No description provided.